Sign in

Jan Schaumann

@jschauma.mstdn.social.ap.brid.gy
83 followers 7 following 632 posts

Vell, I'm just zis guy, you know? 🌉 bridged from ⁂ mstdn.social/@jschauma, follow @ap.brid.gy to interact

PostsRepliesMedia
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 01/10/2026
“Saying that models are “cheating” when they provide answers in the “wrong” way implies they are operating — or can operate — beyond the limits of human control. This, in turn, allows everyone to write off the accountability that clearly lies with the humans in charge of the process.” A hundred […]
mstdn.social
Original post on mstdn.social
011
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 30/09/2026
Oh fucking fantastic. macOS 27 removes support for AFP, and my TimeCapsule can't do SMB, so now I get to redo my entire home NAS setup. Guess that's I get for buying into the Apple ecosystem without buying new hardware every 6 months.
111
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 30/09/2026
When you notice your meat-proxy colleagues become absolutely helpless on their own, remember Sam Altman's goal: “We see a future where intelligence is a utility, like electricity or water, and people buy it from us on a meter” People paying to make themselves dependent on these companies. You […]
mstdn.social
Original post on mstdn.social
218
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 29/09/2026
Lol, nice. Debian linux security update DSA 6528-1: "Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks." "Several", as in... 1,313 CVEs. Enjoy! ✌️ […]
mstdn.social
Original post on mstdn.social
285
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 24/09/2026
This OpEd by Cal Newport is very good. Choice quotes: “OpenAI often discusses these incidents as if it were a passive observer of an autonomous technology — a rhetorical gambit that acts as a smokescreen for bad behavior.” “We need to stop letting a small number of private companies, acting […]
mstdn.social
Original post on mstdn.social
001
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 24/09/2026
The real joke is of course that he probably first wanted to rename it to "American Intelligence", but then he wouldn't be able to tell who's bootlicking or not when saying "AI". As always, it's a loyalty test and fealty signal.
002
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 23/09/2026
New plonk just dropped.
Usenet ASCII art of a person holding a sign that reads "Please don't feed the MEAT-PROXY !"
001
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 22/09/2026
Oh boy. We lost another one. It's so sad. Nothing left but an overeager meat -proxy husk. RIP* (Rest in Pity)
001
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 22/09/2026
Wired's survey of Women Who Work in Tech is depressing precisely because it's not _shocking_ (as in surprising). And compared to 5 years ago, "47% said tech is unchanged or worse for women". Oh, also, guess what: AI makes this worse. "Sloppy, half-assed work gets praise when a man does it with […]
mstdn.social
Original post on mstdn.social
012
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 20/09/2026
And one more*, because Cory Doctorow is rather good at simplifying things. "Remember: every time you repeat a story about how awfully, terribly dangerous their products are, you help them raise more investment capital, which is a key input for their business" […]
mstdn.social
Original post on mstdn.social
003
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 20/09/2026
"I’d like to see somebody get prosecuted for OAI’s recent transgressions. How is that for regulation, for starters? [...] All we get are essays about slowing down and alien minds." pop.rdi.sh/dario-please
pop.rdi.sh
dario, please! - POP RDI; RET;
Your favourite ROP gadget
000
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 19/09/2026
"How To Write With An LLM" sockpuppet.org/blog/2026/09/17/how-… A problem I see is that of course this way of writing is still work and takes time, care, and attention -- exactly what most people using an LLM here are seeking to avoid. Those who _do_ put in this […]
mstdn.social
Original post on mstdn.social
102
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 19/09/2026
Quick reminder: Models Don't Go Rogue mail.cyberneticforests.com/models-d… (Now AI companies and their cultists on the other hand...)
mail.cyberneticforests.com
Models Don't Go Rogue
Stochastic Flocks & Cybersecurity 'Pandemonium' 💡This essay was drafted from my appearance on Mél Hogan's podcast, The Data Fix, discussing the OpenAI / Hugging Face hack. Embedded below or find it on your podcast services here. OpenAI put out its full technical report on the Hugging Face hack this week, alongside
016
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 18/09/2026
The problem - well, one of them, anyway - with government regulations of AI is that it presupposes a benevolent, functioning government. So… yeah.
000
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 18/09/2026
I wasn't even going to post it here, because it's just a rant that felt good to jot down, but since it's now been on the hackernews front page and shared elsewhere, it looks like it touched a nerve: (Read the comments at your own risk. There's brain worms there, too.) […]
mstdn.social
Original post on mstdn.social
3126
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 17/09/2026
Tee hee, HN stumbled upon my AI rant blog post and boy is that a different discussion from Lobsters. ✌️
000
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 15/09/2026
Gell-Mann AInesia effect: The phenomenon of a person rejecting the use of AI in their own area of expertise, but thinking it sure is useful for other areas. With time, the ainesia chips away at the original expertise and the victim begins to self-amputate all actual knowledge, leaving an […]
mstdn.social
Original post on mstdn.social
033
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 14/09/2026
There isn’t a 10% chance that AI will kill all humans in the future via Skynet or the Paperclip Maximizer. But there’s a 100% chance it’s already doing so: mandating water wasting, air polluting, fossil fuel powered data centers, environmental regulations are lifted for these companies and even […]
mstdn.social
Original post on mstdn.social
005
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 13/09/2026
Psst, AI companies, I’ll let you in on a secret: You don’t actually need government regulations or an industry wide moratorium to stop building the torment nexus. Like, if you _actually_ cared and indeed _were_ concerned, you could, you know, just, like, not build it. Nobody’s forcing you to […]
mstdn.social
Original post on mstdn.social
014
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 12/09/2026
Dear journalists: it's not "AI escaped", it's "AI companies failed to restrict the programs". Programs that did exactly what they were instructed to do. By those companies. Place the blame where it belongs.
31062
Reposted by Jan Schaumann
abadidea @0xabad1dea.infosec.exchange.ap.brid.gy · 09/09/2026
Project Glasswing: Claiming to have found 26 thousand real vulnerabilities but only 0.8% of them have resulted in a real fix in a real project after five months is dire. They blame it on the human independent review bottleneck, but human experts being paid for their time definitely have a […]
infosec.exchange
Original post on infosec.exchange
11610
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 08/09/2026
Feels like a Monday when you open the inbox and see "Linux kernel LPEs: ZcopyReaper (CVE-2026-43502) and 20 more". www.openwall.com/lists/oss-security… Various exploits/PoCs here: github.com/NebuSec/CyberMeowfia/tre… While I don't know how […]
mstdn.social
Original post on mstdn.social
100
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 06/09/2026
I still don't know how to handle AI in the CS classroom. I despise it, and I know it robs students of the opportunity to learn, but I also know that literally 100% of students _will_ use it in some form, regardless of course policy. But students also need to learn how to use AI as a tool they […]
mstdn.social
Original post on mstdn.social
112
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 05/09/2026
Young 'uns: it's a bitter lesson to learn, but don't bind your identity to any party, organization, product, company. Recognize your relationship as transactional (employee, customer, consumer, ...) or political (volunteer, party member, supporter, ...) and know that they have no qualms about […]
mstdn.social
Original post on mstdn.social
002
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 05/09/2026
Wtf? Happened to go to IMDB in a browser where I was logged into Amazon, which apparently now automatically automatically creates an account for you there and logs you in and then spams you right away. Motherfuckers.
200
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 03/09/2026
So that log4j thing that came in last week... that's just a nothing burger, right? Claiming it's an RCE in log4j because if you find an endpoint to which you can upload an object and that _then_ de-serializes the attacker controlled data feels like claiming Apache httpd has an RCE because you […]
mstdn.social
Original post on mstdn.social
200
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 03/09/2026
I absolutely detest the use of the word "gadget" in vulnerability reports. It almost always stands in for some hand-wavy "magic happens here" that obscures the lack of a practical exploit path.
010
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 02/09/2026
Hey kids! It's the start of the Fall semester, and I'm again teaching "Advanced Programming in the UNIX Environment". The syllabus and all course materials including all code examples are available here: stevens.netmeister.org/631 As usual, we'll be using #NetBSD as our main platform […]
mstdn.social
Original post on mstdn.social
1529
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 01/09/2026
This has absolutely entered my vocabulary. On the off-chance that you haven't seen this definition yet: Meat proxy 1. A person who forwards AI-generated text, code, or other output without reading, understanding, or validating it. The person acts only as a relay between the AI system and the […]
mstdn.social
Original post on mstdn.social
014
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 01/09/2026
I'm so allergic to AI generated text. "Blah is critical. It's not only X, but also Y. It's blurb. But the key difference is..." and "The smoking gun: blurg" and "And this is exactly why blob". I hate it so much. But now *everybody* produces this type of text left and right, and calling it out […]
mstdn.social
Original post on mstdn.social
122
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 01/09/2026
I took another look at the top 1M domains, and it looks like we're now at just about 50% support for #PQC hybrid key exchange using TLS 1.3 X25519MLKEM768: www.netmeister.org/blog/pqc-use-202… Adoption rate as I've observed it: Date Percent […] [Original post on mstdn.social]
mstdn.social
Original post on mstdn.social
102
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 01/09/2026
I know, I know, LinkedIn. But this post by @boblord regarding that OpenAI sponsored "call for cyberdefense" is spot on. www.linkedin.com/pulse/sounding-ala… The one thing I'd add is that it really isn't a surprise that this is heavy on recommending _more_ […]
mstdn.social
Original post on mstdn.social
000
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 31/08/2026
Ah, I see it was a mistake to return from vacation. Rookie mistake, I admit.
120
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 18/08/2026
AI is notoriously verbose, often producing pages and pages of output that then, inevitably, the recipient feeds back into _their_ AI to summarize. AI companies are charging customers by the token, both input and output. It's almost as if there was some sort of connection there.
011
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 17/08/2026
Pfft, Mondays. Mondays are fine. Know what I hate? AI.
022
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 14/08/2026
Incident: actively exploited CVE Service team: Not to worry. The EoL'd version we run is *much* older than that, so we're not affected. 🤡 Infosec: 🤦‍♂️ (This happens far too often.)
013
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 10/08/2026
You're right - AI _is_ useful. Your use of it provides an important signal to me: 1) For writing: "I didn't care to put the effort in to write this myself." 2) For coding: "I don't care if I understand the solution." 3) For vuln impact analysis: "I don't understand the code base nor the […]
mstdn.social
Original post on mstdn.social
1223
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 09/08/2026
‘“The world looks different now than when we co-founded the climate pledge,” said Margaret Callahan, an Amazon spokeswoman.’ Yeah, no kidding. IT’S ON FUCKING FIRE because of soulless sacks of shit and the corporate bullshitters like you. Climate pledge my ass […]
mstdn.social
Original post on mstdn.social
1514
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 08/08/2026
Couldn't find the first occurrence to repost, but yes, AI companies trying to one-up each other by touting their incompetence to airgap their systems and chest-thumping their wantonly committing cybercrimes with no consequences is a vibe.
Sundar Pichai as a stick figure poking the Gemini logo, saying "Come on. Commit crimes."
0525
Reposted by Jan Schaumann
spooky Deirdre Connolly¹ ² at a distance @durumcrustulum.com · 06/08/2026
"LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time." 👁️👄👁️ 1password.com/blog/why-ai-...
LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time. You can read further details about our findings, observations, and conclusions in the research paper we’ve published alongside this post.
3174121
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 05/08/2026
Hear me out: social media, but you're not allowed to talk about AI, security vulnerabilities, or the orange turd.
100
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 03/08/2026
I've used the same metaphor ("using AI for assignments is like paying somebody to go to the gym for you") for my students for a long time now. www.schneier.com/blog/archives/2026… (Going forward, I may also have to play […]
mstdn.social
Original post on mstdn.social
013
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 28/07/2026
Seeing a lot of "Haha, I asked 'Are you an AI?' and then it said 'yes'." going around, like a big gotcha. I mean, sure, haha, but it could as well have said 'no', so maybe don't start to adopt the slop variation of the stupid tv myth "if you ask a cop if […] [Original post on mstdn.social]
001
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 28/07/2026
Oooh, so fetch! Video recording of my talk "Get in Loser, We're Upgrading the Internet -- Lessons from Deploying Post-Quantum Cryptography across Akamai's global CDN" from #Troopers26 a few weeks ago is now online: youtu.be/U0DGTHweUxg Accompanying blog post […]
mstdn.social
Original post on mstdn.social
013
Reposted by Jan Schaumann
James Smith 💾 @floppy.org.uk · 25/07/2026
RE: mastodon.social/@concretedog/116976… Note that the opt-out mentions username; it also means organisation name, so make sure to opt out those too. And you can replace the list with “- all” to ask for everything under that name to be removed. 3316 requests so far, let’s get […]
mastodon.me.uk
Original post on mastodon.me.uk
3112
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 24/07/2026
I almost got Cunningham'd: Me: "I'm sorry, I don't have the bandwidth to write the article." Them: "No prob. Here, I wrote* it, could you just check it?" Me: starts editing, commenting, rewriting ... Me: "Wait a minute..." *AI slopped copy pasta from random websites
000
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 24/07/2026
I hereby propose “favepalm” as a new social media reaction, complementing “sadfave”. Looking at my average timeline, I’d smash the hell out of that button.
100
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 22/07/2026
So, uhm, at this point, seems like local privilege escalation vulnerabilities are numerous enough that you canwe can pretty much assume that any local user can become root and escape most containers, yes? "FragGap" LPE via IPv4/IPv6 UDP corking path […]
mstdn.social
Original post on mstdn.social
110
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 22/07/2026
Look, I know this is OpenAI wanting to quickly one-up Anthropic in the "see, our model is really dangerous, too" department, but what I'm taking away from this isn't "OpenAI and Hugging Face partner on addressing security incident", but "OpenAI attacked Hugging Face". So when it's your turn to […]
mstdn.social
Original post on mstdn.social
000
Jan Schaumann @jschauma.mstdn.social.ap.brid.gy · 21/07/2026
RE: mastodon.social/@nixCraft/116953574… Lol, nice. I've said it before: linux kernel CVEs are no longer meaningful. You can't assess 432 new CVEs. You basically have to sit and wait to see which ones get a logo and a website or which ones become KEVs to prioritize.
mastodon.social
000